You need to be logged in to post in the forum - Log In

An active JCE Pro Subscription is required to post in the forum - Buy a Subscription

Support is currently Offline

Official support hours
Monday to Friday
09:00 - 17:00 Europe/London (BST)

Please create a new Ticket and we will get back to you as soon as we can.

#100550 Filtering tag attributes on article save does not work correctly

Posted in ‘Editor’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Latest post by Ryan on Wednesday, 17 July 2019 14:30 BST

kunze-medien
Hello Ryan, enclosed a profile, which has forbidden tags and attributes configured, but these won’t be cleared while saving. This manipulation can be done by Firefox HTML-Inspector and is shown by the editor before saving. Example: Ich verwende ein custom filed vom Typ editor, mit der Filtereinstellung safe HTML, und öffne den Beitrag zur Bearbeitung mit einem Benutzer aus der Gruppe Editor welcher mit dem beigefügten Profil verknüft ist. Die Filtereinstellung Plugin-Einstellung funktioniert garnicht. Create a custom field from type editor with filteroption safe HTML. Open an article to edit it as an user who belongs to the group editor and connect him with my profile. By the way, filteroption use settings from plugin doesn't work at all. Attribute style is now forbidden in this case and I’m editing it now with FF-Inspector and create an allowed tag like this:

<p style="text-align: right;">Lorem ipsum...</p>
This is displayed and formatted correctly by the editor, but I expected that this style attribute and its value would be removed before saving. But it doesn’t. The attribute gets removed after I start editing the article again but it doesn’t get cleared completely. Parts of value will now be shown as attribute like this:

<p text-align:="">Test</p>
How do I configure this correctly in profile or is it a bug? Regards

Attachments

jce_editor_profile_2019_07_16_KM.zip

Ryan
As you already have "style" in the Prohibited Attributes field, you do not need the regular expression value you have added to the Prohibited Attribute Values field.

You can also alter the event expression so that it is just on([a-z]+)

Ryan Demmer

Lead Developer / CEO / CTO

Just because you're not paranoid doesn't mean everybody isn't out to get you.

kunze-medien
We already done this, but the problem still exists.
We hope You will finde a solution soon.

Ryan
This has been fixed in JCE Pro 2.7.15 - https://www.joomlacontenteditor.net/downloads/editor/pro/latest

Ryan Demmer

Lead Developer / CEO / CTO

Just because you're not paranoid doesn't mean everybody isn't out to get you.